Skip to content

Agents and permissions ​

Lanzer works with any agent that speaks the Agent Client Protocol. Pick one in .env:

shell
LANZER_ACP_COMMAND=npx
LANZER_ACP_ARGS=["claude-agent-acp"]
LANZER_ACP_MODEL=sonnet
shell
# sign in first: npx -y @openai/codex login
LANZER_ACP_COMMAND=npx
LANZER_ACP_ARGS=["-y","@agentclientprotocol/codex-acp"]
LANZER_ACP_PROVIDER=codex
LANZER_ACP_MODEL=gpt-5.5
shell
LANZER_ACP_COMMAND=npx
LANZER_ACP_ARGS=["-y","@google/gemini-cli","--acp"]

Variables ​

VariableExampleMeaning
LANZER_ACP_COMMAND, LANZER_ACP_ARGSnpx, ["claude-agent-acp"]The agent to start.
LANZER_ACP_PROVIDERcodexOnly matters for Codex.
LANZER_ACP_MODELsonnet, gpt-5.5The agent's own alias, not an API id.
LANZER_ACP_EFFORTmediumReasoning effort.
LANZER_ACP_MAX_ATTEMPTS2Prompts per session.
LANZER_ACP_ALLOWread,edit,search,think,otherWhat the agent may do.
LANZER_ACP_ISOLATED1Run without your own agent setup.

Model names

Use the agent's alias (sonnet, opus, haiku), not an API id like claude-sonnet-4-6. An unknown alias is skipped and the agent's default is used.

Permissions ​

A run is unattended, so by default the agent may only read, edit, search, think and other (where skills load). No shell, no deleting or moving files, no network.

shell
# also allow shell commands
lox-lanzer generate ./examples/hello.lanzer --allow read,edit,search,think,other,execute
# no policy at all
lox-lanzer generate ./examples/hello.lanzer --allow-all

The list is read literally: naming kinds limits the run to exactly those. Refusals print as [perm] denied execute: … and the next fix prompt names them.

What confines files:

  • Writes stay in the campaign's workspace; reads in the workspace plus the grammar, reference files and skill. Claude uses its own file tools, so it keeps to its session roots instead: the same folders, but all writable.
  • After the run, a declared file left unwritten, or a changed support file, fails it. Other new files are reported.
  • Claude runs in acceptEdits mode, never bypassPermissions.

Shell access

An agent that can run shell commands steps around every file check. At scale, run in a container.

Codex ​

Codex through codex-acp gets Lanzer's tools and real sessions, like Claude. Two limits: its token counts cover only the last model request, and whether it asks before running a shell command (so that leaving out execute is enforced) is not verified yet.

Released under the MIT License.